9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-44083
Software Genérico General
7.5
HIGH
EPSS
11.7%
2024 2 PoCs

ida64.dll in Hex-Rays IDA Pro through 8.4 crashes when there is a section that has many jumps linked, and the final jump corresponds to the payload from where the actual entry point will be invoked. NOTE: in many use cases, this is an inconvenience but not a security issue.

CVE-2024-11322
PowerPanel Business General
7.5
HIGH
EPSS
0.8%
2024 CWE-287 1 PoC

A denial-of-service vulnerability exists in CyberPower PowerPanel Business (PPB) 4.11.0. An unauthenticated remote attacker can restart the ppbd.exe process via the PowerPanel Business Service Watchdog service listening on TCP port 2003. The attacker can repeatedly restart ppbd.exe to render it unavailable.

CVE-2024-22641
Software Genérico General
7.5
HIGH
EPSS
9.0%
2024 1 PoC

TCPDF version 6.6.5 and before is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted SVG file.

CVE-2024-32825
Simply Static General ⚡ nuclei
7.5
HIGH
EPSS
25.8%
2024 CWE-201 0 PoCs

Insertion of Sensitive Information Into Sent Data vulnerability in Simply Static Simply Static simply-static.This issue affects Simply Static: from n/a through <= 3.1.3.

CVE-2024-12085
Software Genérico General
7.5
HIGH
EPSS
19.1%
2024 CWE-908 1 PoC

A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.

CVE-2024-55568
Software Genérico General
7.5
HIGH
EPSS
0.1%
2024 2 PoCs

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. The absence of a NULL check leads to a Denial of Service when an attacker sends malformed MM packets to the target.

CVE-2024-55196
Software Genérico General
7.5
HIGH
EPSS
0.0%
2024 1 PoC

Insufficiently Protected Credentials in the Mail Server Configuration in GoPhish v0.12.1 allows an attacker to access cleartext passwords for the configured IMAP and SMTP servers.

CVE-2024-49193
Software Genérico General
7.5
HIGH
EPSS
0.1%
2024 1 PoC

Zendesk before 2024-07-02 allows remote attackers to read ticket history via e-mail spoofing, because Cc fields are extracted from incoming e-mail messages and used to grant additional authorization for ticket viewing, the mechanism for detecting spoofed e-mail messages is insufficient, and the support e-mail addresses associated with individual tickets are predictable.

CVE-2024-28716
Software Genérico General
7.5
HIGH
EPSS
2.2%
2024 2 PoCs

An issue in OpenStack Storlets yoga-eom allows a remote attacker to execute arbitrary code via the gateway.py component.

CVE-2024-33605
Multiple MFPs (multifunction printers) General ⚡ nuclei
7.5
HIGH
EPSS
60.2%
2024 CWE-22 3 PoCs

Improper processing of some parameters of installed_emanual_list.html leads to a path traversal vulnerability. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

CVE-2024-44375
Software Genérico General
7.5
HIGH
EPSS
0.4%
2024 1 PoC

D-Link DI-8100 v16.07.26A1 has a stack overflow vulnerability in the dbsrv_asp function.

CVE-2024-42011
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

The Spotify app 8.9.58 for iOS has a buffer overflow in its use of strcat.

CVE-2024-34659
Group Sharing General
7.5
HIGH
EPSS
0.4%
2024 1 PoC

Exposure of sensitive information in GroupSharing prior to version 13.6.13.3 allows remote attackers can force the victim to join the group.

CVE-2024-4227
gSOAP General
7.5
HIGH
EPSS
0.2%
2024 CWE-834 1 PoC

In Genivia gSOAP with a specific configuration an unauthenticated remote attacker can generate a high CPU load when forcing to parse an XML having duplicate ID attributes which can lead to a DoS.

CVE-2024-25253
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

Driver Booster v10.6 was discovered to contain a buffer overflow via the Host parameter under the Customize proxy module.

CVE-2024-49420
GamingHub General
7.5
HIGH
EPSS
1.4%
2024 1 PoC

Improper handling of responses in GamingHub prior to version 6.1.04.6 in Korea, 7.1.03.7 in Global allows remote attackers to launch arbitrary activity.

CVE-2024-57716
Software Genérico General
7.5
HIGH
EPSS
0.0%
2024 1 PoC

An issue in trenoncourt AutoQueryable v.1.7.0 allows a remote attacker to obtain sensitive information via the Unselectable function.

CVE-2024-28442
Software Genérico General
7.5
HIGH
EPSS
0.3%
2024 2 PoCs

Directory Traversal vulnerability in Yealink VP59 v.91.15.0.118 allows a physically proximate attacker to obtain sensitive information via terms of use function in the company portal component.

CVE-2024-51982
HL-L8260CDN General
7.5
HIGH
EPSS
1.1%
2024 CWE-1286 2 PoCs

An unauthenticated attacker who can connect to TCP port 9100 can issue a Printer Job Language (PJL) command that will crash the target device. The device will reboot, after which the attacker can reissue the command to repeatedly crash the device. A malformed PJL variable FORMLINES is set to a non number value causing the target to crash.

CVE-2024-34669
Samsung Mobile Devices General
7.5
HIGH
EPSS
5.1%
2024 1 PoC

Out-of-bounds write in parsing h.263+ format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.